WinSecWiki > Security Settings > Local Policies > Audit Policy > Audit Logon > Logon

Logon

This category logs every attempt to logon to the local computer regardless of logon type or account type (domain/local). To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event IDTitle
4624 An account was successfully logged on.
4625 An account failed to log on.
4648 A logon was attempted using explicit credentials

Back to top

 

Additional Resources